Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2847▼ 221 respecto a la semana anterior
Críticas / altas1332▼ 166 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
–

1066 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.43%—Mage-people BUS Ticket Booking With Seat Reservation2/8/202317/6/2026
The Bus Ticket Booking with Seat Reservation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab_date' and 'tab_date_r' parameters in versions up to, and including, 5.2.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
ModificadaMedia (6.1)0.50%—Phpjabbers Time Slots Booking Calendar1/8/202317/6/2026
Existe una vulnerabilidad de Cross Site Scripting (XSS) en el parámetro "theme" de preview.php en Time Slots Booking Calendar v3.3 de PHPJabbers.
ModificadaAlta (8.8)0.76%—Phpjabbers Time Slots Booking Calendar1/8/202317/6/2026
En Time Slots Booking Calendar 3.3 de PHP Jabbers, la falta de verificación al cambiar una dirección de correo electrónico y/o contraseña (en la Página de Perfil) permite a atacantes remotos tomar el control de cuentas.
ModificadaCrítica (9.8)0.77%—Phpjabbers Time Slots Booking Calendar1/8/202317/6/2026
La enumeración de usuarios se encuentra en Time Slots Booking Calendar v3.3 de PHPJabbers. Este problema se produce durante la recuperación de contraseñas, donde una diferencia en los mensajes podría permitir a un atacante determinar si el usuario es válido o no, permitiendo un ataque de fuerza bruta con usuarios…
ModificadaCrítica (9.8)0.99%—Phpjabbers Time Slots Booking Calendar1/8/202317/6/2026
La validación incorrecta del parámetro de contraseña en Time Slots Booking Calendar v 3.3 de PHPJabbers resulta en contraseñas inseguras.
ModificadaMedia (6.1)0.50%—Phpjabbers Time Slots Booking Calendar1/8/202317/6/2026
Existe una vulnerabilidad de Cross Site Scripting (XSS) en el parámetro "cid" de preview.php en Time Slots Booking Calendar v3.3 de PHPJabbers.
ModificadaMedia (5.4)0.56%—Gzscripts Availability Booking Calendar PHP27/7/202317/6/2026
A vulnerability, which was classified as problematic, was found in GZ Scripts Availability Booking Calendar PHP 1.0. This affects an unknown part of the file /index.php?controller=GzUser&action=edit&id=1 of the component Image Handler. The manipulation of the argument img leads to cross site scripting. It is possible…
ModificadaMedia (5.4)0.56%—Gzscripts Availability Booking Calendar PHP27/7/202317/6/2026
A vulnerability, which was classified as problematic, has been found in GZ Scripts Availability Booking Calendar PHP 1.0. Affected by this issue is some unknown functionality of the file index.php of the component HTTP POST Request Handler. The manipulation of the argument promo_code leads to cross site scripting. The…
ModificadaMedia (6.1)0.41%—Booking Calendar Project Booking Calendar18/7/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in CodePeople Booking Calendar Contact Form plugin <= 1.2.40 versions.
ModificadaMedia (4.3)0.39%—Thimpress WP Hotel Booking12/7/202317/6/2026
The WP Hotel Booking plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.10.1. This is due to missing or incorrect nonce validation on the admin_add_order_item() function. This makes it possible for unauthenticated attackers to add an order item via a forged request…
ModificadaMedia (6.1)0.52%—Gzscripts GZ Multi Hotel Booking System10/7/202317/6/2026
A vulnerability was found in GZ Scripts GZ Multi Hotel Booking System 1.8. It has been classified as problematic. Affected is an unknown function of the file /index.php. The manipulation of the argument adults/children/cal_id leads to cross site scripting. It is possible to launch the attack remotely. VDB-233358 is…
ModificadaMedia (6.1)0.51%—Gzscripts PHP GZ Hotel Booking Script10/7/202317/6/2026
A vulnerability, which was classified as problematic, was found in GZ Scripts PHP GZ Hotel Booking Script 1.8. This affects an unknown part of the file /load.php. The manipulation of the argument first_name/second_name/phone/address_1/country leads to cross site scripting. It is possible to initiate the attack…
ModificadaMedia (6.1)0.38%—Gzscripts Ticket Booking Script10/7/202317/6/2026
A vulnerability, which was classified as problematic, has been found in GZ Scripts Ticket Booking Script 1.8. Affected by this issue is some unknown functionality of the file /load.php. The manipulation of the argument first_name/second_name/phone/address_1/country leads to cross site scripting. The attack may be…
ModificadaMedia (5.4)0.51%—Gzscripts Event Booking Calendar10/7/202317/6/2026
A vulnerability classified as problematic has been found in GZ Scripts Event Booking Calendar 1.8. Affected is an unknown function of the file /load.php. The manipulation of the argument first_name/second_name/phone/address_1/country leads to cross site scripting. It is possible to launch the attack remotely. The…
ModificadaMedia (6.1)0.39%—Gzscripts Time Slot Booking Calendar PHP7/7/202317/6/2026
A vulnerability was found in GZ Scripts Time Slot Booking Calendar PHP 1.8. It has been declared as problematic. This vulnerability affects unknown code of the file /load.php. The manipulation of the argument first_name/second_name/phone/address_1/country leads to cross site scripting. The attack can be initiated…
ModificadaMedia (6.1)0.39%—Gzscripts Availability Booking Calendar PHP7/7/202317/6/2026
A vulnerability was found in GZ Scripts Availability Booking Calendar PHP 1.8. It has been classified as problematic. This affects an unknown part of the file load.php of the component HTTP POST Request Handler. The manipulation of the argument cid/first_name/second_name/address_1/country leads to cross site…
ModificadaMedia (4.3)0.30%—Salonbookingsystem Salon Booking System28/6/202317/6/2026
The Salon Booking System plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.4.6. This is due to missing or incorrect nonce validation on the 'save_customer' function. This makes it possible for unauthenticated attackers to change the admin role to customer or change…
ModificadaMedia (4.8)0.44%—Magepeople Booking & Rental Manager23/6/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in MagePeople Team Booking and Rental Manager for Bike plugin <= 1.2.1 versions.
ModificadaMedia (4.3)0.48%—Vcita Online Booking & Scheduling Calendar9/6/202317/6/2026
The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vcita_save_settings_callback function in versions up to, and including, 4.4.6. This makes it possible for authenticated attackers with minimal…
ModificadaMedia (6.5)0.39%—Vcita Online Booking & Scheduling Calendar3/6/202317/6/2026
The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the vcita_logout_callback function in versions up to, and including, 4.5. This makes it possible for unauthenticated to logout a vctia connected account which…
ModificadaMedia (5.4)0.70%—Vcita Online Booking & Scheduling Calendar3/6/202317/6/2026
The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vcita_logout_callback function in versions up to, and including, 4.2.10. This makes it possible for authenticated attackers with minimal…
ModificadaMedia (5.3)0.64%—Vcita Online Booking & Scheduling Calendar3/6/202317/6/2026
The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized medication of data via the /wp-json/vcita-wordpress/v1/actions/auth REST-API endpoint in versions up to, and including, 4.4.2 due to a missing capability check on the processAction function. This makes it…
ModificadaMedia (6.1)0.60%—Vcita Online Booking & Scheduling Calendar3/6/202317/6/2026
The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'business_id' parameter in versions up to, and including, 4.3.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
ModificadaMedia (4.8)0.37%—Booking-wp-plugin Bookly2/6/202317/6/2026
The Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via service titles in versions up to, and including, 21.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative privileges to inject arbitrary web scripts in pages…
ModificadaAlta (8.8)0.26%—Bookingultrapro Booking Ultra PRO Appointments Booking Calendar24/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Booking Ultra Pro Appointments Booking Calendar Plugin plugin <= 1.1.4 versions.
Orbitaley — Vulnerabilidades